List Category Posts WordPress Plugin Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the List Category Posts plugin for WordPress, affecting all versions through 0.95.0. The issue arises from the 'sanitize_status' function, which fails to properly authorize requests. This flaw enables authenticated attackers with contributor-level access and above to access titles, full content, excerpts, dates, authors, and custom-field metadata from other users' pending-review, scheduled, and trashed posts. The vulnerability can be exploited by embedding a crafted [catlist] shortcode into their own draft and previewing it. This issue bypasses a previous fix for a similar vulnerability, CVE-2025-11377, which was addressed in version 0.93.0.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive information, including post titles, full content, excerpts, dates, authors, and custom-field metadata from other users' posts in pending-review, scheduled, and trashed states.

Reproduction

To reproduce this vulnerability, an authenticated user with contributor-level access or higher can embed a crafted [catlist] shortcode into a draft post. When the post is previewed, the shortcode will trigger the vulnerability, exposing sensitive information from other users' posts that are pending review, scheduled, or trashed.

Remediation

Users are advised to update the List Category Posts plugin to version 0.96.0 or later, where this vulnerability has been addressed.

Added: Jul 16, 2026, 4:33 AM
Updated: Jul 16, 2026, 4:33 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
6.4
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.